1. Record where AI is used
Create an inventory of AI-enabled tools and integrations, including features inside ordinary business software. Record purpose, owner, users, data categories, suppliers and downstream actions. Include experiments that handle real information, not only systems described as production services. An inventory makes it possible to ask the right questions when a supplier or business process changes.
Distinguish drafting assistance from automated action. A tool that suggests internal wording presents different consequences from one that changes a customer’s record or influences an employment decision. Describe the actual use rather than assigning risk from the product name alone. Identify who can approve, pause and retire each use, and ensure that those responsibilities are accepted.
2. Establish data handling conditions
For UK organisations, the UK GDPR and Data Protection Act 2018 remain relevant when AI processes personal information. Consider purpose, lawful basis, minimisation, transparency and the rights of affected people. A data protection impact assessment may be required where processing is likely to result in high risk. Obtain appropriate legal or privacy advice for your circumstances.
Review supplier contracts for training use, retention, subprocessors, security obligations and transfers outside the UK. Avoid putting credentials or unnecessary sensitive information into prompts. Set rules for approved tools and explain how staff can request a suitable alternative. A blanket prohibition without a practical route for legitimate work can leave actual use difficult to observe.
3. Connect controls to known risks
The NIST AI Risk Management Framework organises work around Govern, Map, Measure and Manage. It is a voluntary reference, not a certification that makes a deployment safe. Use it to structure questions about context, evaluation and responsibility. Translate those questions into concrete controls that someone can carry out and review.
The OWASP project on large language model application risks provides a security reference for issues such as prompt injection and inappropriate handling of outputs. Apply least-privilege access, tool restrictions and validation where relevant. A well-written prompt is not a substitute for a permission boundary enforced by the surrounding application.
4. Make human oversight meaningful
Oversight requires access to the evidence, time to inspect it and authority to disagree. Show reviewers what the system used and what action is proposed. Avoid an interface that makes approval easy but correction impractical. Explain which tasks remain outside the system’s scope and where staff should send a case that needs judgement.
Define review requirements according to consequences. An internal draft and a decision affecting a person’s access to a service should not share an automatic approval rule merely because both use the same model. Where decisions have legal or similarly significant effects, seek advice on the applicable rules for automated decision-making and relevant safeguards before deployment.
5. Evaluate changes and handle incidents
Keep a record of prompts, retrieval configuration, model selection and integration changes where these affect behaviour. Re-run relevant evaluations when a supplier or configuration changes, and document the result. Include unusual inputs, unsupported requests, permission boundaries and harmful failure modes. A single average quality figure can conceal the cases with the most serious consequences.
Set an incident route that people can use without technical expertise. Record what happened, affected data, downstream actions and immediate containment. Provide a way to pause the system and return to a manual process. Involve security, privacy and business owners as appropriate; an AI-related incident may also require the organisation’s established breach or safeguarding procedures.
6. Agree the operating documentation
A governance engagement can be scoped around an inventory, acceptable-use rules, data handling conditions, evaluation requirements and a documented incident process. Agree which deliverables are required and who will maintain them. Policy wording should correspond to controls your organisation can actually operate. Ownership of updates matters as much as ownership of the initial document.
Consult the ICO’s AI guidance for UK privacy considerations and the National Cyber Security Centre for security resources. Where operations or customers cross borders, obtain advice on additional obligations, including EU rules where applicable. This service supports operational governance; it does not replace legal advice or confer certification.
